
Block Object Injection in Booklovers Theme by Verifying Version Before 2.13.1
The NVD rates CVE-2026-62045 as critical because it allows unauthenticated attackers to inject objects via deserialization flaws in older Booklovers versions.
Everything Vector Update has reported about WordPress: 5 stories, newest first. Part of our Vulnerabilities coverage.

The NVD rates CVE-2026-62045 as critical because it allows unauthenticated attackers to inject objects via deserialization flaws in older Booklovers versions.

The NVD rates this remote code execution vulnerability in the 3D Product Configurator plugin as critical due to missing authentication checks.

An unauthenticated privilege escalation flaw in Blocksy Companion versions up to 2.1.58 allows attackers to bypass security checks and create seller accounts.

A critical flaw in the Partiso WordPress theme allows attackers to inject objects via untrusted data, affecting versions up to 1.1.13.

A critical vulnerability in ThemeREX Edema versions up to 1.2.2.2 allows object injection via untrusted data deserialization, requiring immediate action.